VDB
Sign up
MEDIUM6.1

PYSEC-2026-1102

aiohttp Cross-site Scripting vulnerability on index pages for static file handling

Quick fix

PYSEC-2026-1102 — aiohttp: upgrade to the fixed version with the command below.

pip install --upgrade 'aiohttp>=3.9.4'

Details

### Summary

A XSS vulnerability exists on index pages for static file handling.

### Details

When using `web.static(..., show_index=True)`, the resulting index pages do not escape file names.

If users can upload files with arbitrary filenames to the static directory, the server is vulnerable to XSS attacks.

### Workaround

We have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected.

Other users can disable `show_index` if unable to upgrade.

-----

Patch: https://github.com/aio-libs/aiohttp/pull/8319/files

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/aiohttp
Introduced in: 0Fixed in: 3.9.4
Fixpip install --upgrade 'aiohttp>=3.9.4'

References